Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Don't be the IT manager who lets unencrypted data go

Products to encrypt data
Storage Alert By Mike Karp , Network World , 06/23/2005
Sign up for this newsletter now!

Storage analyst Deni Connor focuses on storage, application and infrastructure management in this twice-weekly newsletter.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Capturing top position in last week's Stupid IT Tricks Competition are the good folks at CardSystems Solutions in Atlanta. This company processes credit card and other payments for banks and merchants and, inadvertently, for hackers as well. Its unencrypted data was hacked last month, with the likely result that information on 40 million credit card accounts was compromised.

America Express, Discover, MasterCard, Visa, take your pick (somebody else apparently already has) were all affected. Check this month's credit card statements carefully when they arrive.

Questionable management of "secure data" is in the news far too frequently these days. Ameritrade, Bank of America, Citigroup, Lexus/Nexus, Time Warner, most of which I reported on last month, have all dropped the ball in recent months when it comes to data security. Oftentimes the data just "disappears" in transit to a third-party data repository like Iron Mountain; sometimes it goes missing when being shipped between facilities within the same company, and on frequent occasions, it is actively attacked from both inside and outside the firewall as was the case with CardSystems. In all instances listed above none of the data was encrypted, which certainly leads us to wonder about the seemingly cavalier attitude assumed by the companies to whom it was entrusted.

IT managers tend to avoid encrypting data for any of several reasons. In some cases, there is no corporate emphasis on security to support investment in encryption technology. More frequently, they are concerned that encryption will add to the time it takes to access or back up data, so amid all their other time constraints they avoid adding what seems to be another "cycle-sucker" to their operations. Most frequently, I suspect they just keep their fingers crossed and hope that when something hits the fan it won't occur at their shop.

Lots of alternatives are available to support encryption of data at rest. Security software vendors like Decru (acquired last week by Network Appliance), Neoscale and Vormetric offer solutions that can be dropped-in, appliance-like, in most environments. These will take care of protecting data on your storage-area network.

If your concern is about encrypting tapes to protect them while they travel offsite, consider the offerings from FalconStor and Intradyn.

Deni Connor is principal analyst for Storage Strategies NOW.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Partner Content

Explore the Ultrium Edge

The powerful tape technology can address data security with tape encryption as well as long term data protection.

Find Out More

Disk and Tape Square Off

Discover what disk and tape really cost and which solution provides lower total cost of ownership and optimizes energy use for your organization

Download this White Paper

Don't Fall for the Myths

The Clipper Group explores the truth behind the myths of tape, digging into the misconceptions in the disk vs. tape debate.

Review this information

information examination

An examination of information security issues, methods and securing data with LTO-4 tape drive encryption

Read this analysis

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed